Skip to main content
FeaturedIndustry Updates and Thought LeadershipMarketo Engage and Marketing Ops Execution

What You Can Actually Do with the Marketo Engage MCP Server (and Marketo AI Skills)

By September 28, 2026No Comments

I've lost track of how many times someone on a marketing ops team has asked me a version of the same question: "Can you just check why this campaign didn't fire?" or "Can you pull every draft email sitting in the Q4 folder?" Small ask. Five minutes of clicking through Marketo to answer it. Except it's never just one of those a day. It's fifteen, and they all land between meetings.

That's the gap Adobe is trying to close with the Marketo Engage MCP server, and it's worth understanding what it actually does before you decide whether it's useful for your team.

First, what MCP is and isn't

Model Context Protocol is a standard way to connect an AI tool, like Claude Desktop or Claude Code, to an external system. Adobe hosts the Marketo MCP server, your AI tool sends it a request, and it executes the matching Marketo REST API call with credentials you supply. That's it. No new software to install. No AI model living inside Marketo.

How it works
One prompt in, one Marketo API call out
1
Your AI toolClaude Desktop, Claude Code or another MCP client
sends a request
2
Marketo MCP serverHosted by Adobe. 120+ tools, read and write.
runs the matching REST API call
3
Your Marketo instanceAccessed with credentials you supply, per request
  • No new software to install
  • No AI model inside Marketo
  • Doesn't train on your data
  • Munchkin ID must be allowlisted
The MCP server is a translator between your AI tool and the Marketo REST API. It doesn't store or learn from your instance data.

Worth updating here: when I first wrote this, MCP was read-only. That's changed. The native server now exposes over 120 tools, and a meaningful chunk of them write, not just read. You can create and modify smart list rules, edit flow step actions, and merge or delete leads through it. Cloning smart campaigns via API used to be the ceiling; editing their actual logic through an agent wasn't possible before. It is now. So "MCP" is no longer shorthand for "can't touch anything." The safety net is tool-level permissioning, not a lack of write access, and that permissioning is something you have to set up deliberately (more on that below).

It still doesn't train on your data, doesn't make decisions for you unsupervised if you've configured approvals correctly, and each Munchkin ID has to be explicitly allowlisted.

Instance audits without the click-through

This is the one I'd reach for first. "List all folders in Marketo" or "Show me all draft emails" used to mean opening Marketo, navigating three levels deep, and manually noting what you find. Now it's a prompt. For anyone doing instance audits, cleanup projects, or onboarding onto a new client's Marketo, MCP turns a lot of that reconnaissance work into a conversation instead of a scavenger hunt.

Faster lead and list troubleshooting

"Find the lead with email jane@example.com" and "add lead ID 12345 to the Q2 MQL list" are exactly the kind of one-off requests that pile up in a shared Slack channel. Being able to ask your AI tool directly, and get an answer pulled straight from Marketo, cuts out the back-and-forth.

Program and campaign visibility, now with editing

Cloning programs, browsing by tag, checking which smart campaigns are active right now: still all useful. What's changed since I first wrote this section is the caveat. Smart List and Smart Campaign create and update tools are live in the native MCP now. That's a real shift: MCP went from a lens into your instance to a tool that can build and modify inside it. An agent can add a smart list rule, wire up a new flow step, and point it at an email asset, all through conversation.

The catch is that "can" and "should, unsupervised" are two different questions. Every write or delete tool call should sit behind an approval step until you've had time to trust the setup. More on that in the security section below.

Bulk export, without opening the UI

"Create a bulk export of leads created in the last 30 days" is a real prompt you can run today. For anyone who's scripted around the bulk export API before, this is a meaningfully faster path to the same result.

Marketo AI Skills: a different tool for a different job

Separate from MCP, Adobe also ships a few purpose-built skills inside Marketo itself, and they're worth knowing about because they solve problems MCP isn't built for.

Side by side
MCP server vs. Marketo AI Skills
Outside Marketo

Marketo Engage MCP server

Connects your own AI tool to your instance through the REST API.

  • Instance audits and folder lookups
  • Lead and list troubleshooting
  • Program and campaign browsing, now with editing
  • Bulk exports by prompt
Inside Marketo

Marketo AI Skills

Purpose-built skills that ship in the platform.

  • Investigate LeadsWhy didn't this person hit MQL? Read-only.
  • Validate ProgramsQA pass across a program's components
  • Import LeadsDedupes and normalizes fields on import
  • Product KnowledgeQ&A over Adobe's documentation
MCP is general-purpose access to your instance. AI Skills each solve one specific problem inside Marketo.

Investigate Leads answers the question every campaign manager has asked at least once: "why didn't this person hit MQL?" It pulls the lead's activity and configuration history and gives you a plain-language answer, whether that's a score eight points short of threshold or a marketing-suspended flag quietly excluding them from every send. It's read-only, and it can't explain anything that happened outside Marketo, like a manual removal by a colleague.

Validate Programs runs a QA pass across a program's components, emails, landing pages, campaigns, and flags what passed and what didn't. Good for a pre-launch check, or for auditing programs you've inherited from someone else.

Import Leads is worth knowing about too. It deduplicates a lead list on import and normalizes fields against a standard, country values against ISO codes, for example, so you're not cleaning that up after the fact.

Product Knowledge is the least flashy but maybe the most quietly useful: it's a Q&A layer over Adobe's own documentation, right inside the platform. It won't touch your specific instance data, but for "what's the actual difference between Registered and Attended status," it beats digging through Experience League.

Beyond the native tool set

One more thing worth knowing: the native MCP's 120-ish tools don't cover the full Marketo REST API. There's a wider set of endpoints, the kind you'd normally reach through custom scripting, that aren't exposed as MCP tools yet. If your use case needs something the native server doesn't offer, that gap is closeable with custom tooling rather than a hard wall, worth factoring in if you're scoping a project that needs more than the out-of-the-box tool list.

The part that shouldn't get skipped

None of this is worth using without a dedicated API user scoped to only what's needed, and it's worth testing in a sandbox before anyone relies on it for production decisions. Adobe says as much directly, and it's good advice regardless of the vendor. Credentials get sent per request, and each Munchkin ID has to be explicitly allowlisted.

With write and delete tools now live, the governance question is no longer just "who has access," it's "which specific actions can this agent take without asking first." Most MCP clients let you set approval rules per tool, or in bulk for all read-only tools versus all write tools. Set anything destructive, deletes, merges, updates, to require approval until you've watched it behave correctly a few times. Read-only lookups are a reasonable place to relax that.

Governance
Set approvals by what a tool can change

Read-only tools

Reasonable place to relax approvals
  • List folders and draft emails
  • Find a lead by email
  • Check which smart campaigns are active
  • Browse programs by tag

Write and delete tools

Require approval until proven
  • Create or modify smart list rules
  • Edit flow step actions
  • Update records
  • Merge or delete leads
50,000Every MCP call, read or write, draws from the same daily API quota your other integrations share.
Start with a dedicated, narrowly scoped API user, test in a sandbox, and loosen approvals only after you've watched the agent behave correctly.

It's also worth knowing that every MCP call draws from your standard daily API quota, the same 50,000-call ceiling your other integrations share. If you build anything that runs MCP calls on a schedule or in response to high-volume triggers, that's budget you're spending, and it's worth watching if you've got other integrations competing for the same quota.

Where this actually lands

MCP and the Marketo AI skills aren't going to replace a marketing ops team, and Adobe isn't pretending otherwise. What they will do is take a real chunk of the repetitive, click-heavy work off your plate: the lookups, the status checks, the "can you just tell me why" questions, and now, with appropriate guardrails, some of the routine editing too.

Now that write access exists, a few applications worth considering: bulk hygiene sweeps, having an agent scan every active smart campaign for a specific outdated rule (an old landing page URL, say) and propose the fix for you to approve in one pass, rather than opening each campaign one at a time. For teams running multiple Marketo instances across brands or business units, an agent can compare naming conventions or smart list logic across instances and flag where they've drifted, something that's genuinely tedious to check by hand. And ahead of a send, an agent could walk a new smart campaign's rules and flow steps looking for the kind of thing that normally only surfaces after launch, like a wait step that got skipped or a segment sized far outside what you'd expect.

Example: replacing an outdated landing page URL
Same fix, different place for the judgment call
Click-through audit
Open campaign 1→Check rules→Fix→Open campaign 2→… repeat for every campaign
With an agent
Agent scans every active smart campaign→Proposes the fix→You approve in one pass
The agent does the searching. You still make the decision, once, at the approval prompt.

None of that replaces judgment. It just means the judgment call happens at an approval prompt instead of during a click-through audit.

If you're weighing whether this is worth setting up for your team, or want a second opinion on where the guardrails should sit, send us a note. We'd love to hear what you're seeing:

info@attributa.io
Tom Fast
About the author

Tom Fast

Marketing Attribution Expert, Attributa

Tom Fast is a marketing attribution expert who helps B2B teams get clarity on what's actually driving pipeline. He has 8+ years of experience in marketing attribution, including 6+ years at Adobe supporting Marketo Measure, where he worked across 300+ client instances. Tom hosts Marketo Measure office hours and holds multiple certifications across leading marketing and analytics platforms.

8+ yearsin marketing attribution
6+ yearsat Adobe on Marketo Measure
300+client instances